European Data Act – one year after

Views: 67

The EU Data Governance Act. DGA became applicable in September 2025; it reshaped corporate and consumers access, by assisting sharing and migrating devices/cloud data in the EU member states. During a year in application, it has accelerated the EU, national and corporate compliance, introduced stricter contractual terms and paved the way for upcoming design mandates. The act introduced mandatory cloud switching rights that limit vendor lock-in for Software as a Service (SaaS) and other cloud services in the member states, noted the Commission. 

Background
The European DGA marked an important step in the EU’s efforts to make more data available for reuse while keeping trust and legal safeguards in place. The Act was designed to unlock data that cannot be shared openly, such as sensitive public sector, business-to-government or personal data, and to do so in a safe and controlled way.
During its first year of application, the EU states began establishing national single information points for protected public sector data, while the European Commission developed common tools, guidance and registries to support a more harmonised approach. New rules for data intermediaries and data altruism organisations also started to form, helping clarify how data can be shared responsibly across borders and sectors.
The past year has shown that the legal implementation takes time: the EU member states have been progressing at different speeds, and many public bodies are still adapting their processes, skills and IT systems, notes the Commission. At the same time, the first practical benefits are becoming visible: clearer information on existing data, more transparency around access conditions, as well as growing awareness among researchers and businesses of new reuse opportunities enabled by the Act.
Looking ahead, notes the Commission, the focus will shift from setting up to scaling up; thus, as national services mature and more data becomes discoverable, the DGA is expected to play a stronger role in supporting innovation, research and evidence-based policymaking. Continued cooperation, shared standards and user feedback will be key to ensuring that the Act delivers on its promise of data sharing built on trust.
More on the issue in: https://data.europa.eu/en/news-events/news/data-governance-act-after-one-year-ambition-action

Building the EU-wide single market for data
Data is reshaping the way people produce, consume and live: from real-time navigation to improved personalised medicine, precision farming, or reducing CO₂ emissions, data is a key ingredient for innovative products and services.
To harness the value of data for the benefit of the European economy and society, the European strategy for data (only available from February 2020) set out the path to the creation of Common European Data Spaces in a number of strategic fields: health, agriculture, manufacturing, energy, mobility, finance, public administration, skills, the European Open Science Cloud and the green deal. Since then, data spaces have emerged in other important areas such as media, language, tourism, research and innovation, and cultural heritage. Together, the data spaces will gradually be interconnected to form the EU-wide single market for data. Common European Data Spaces are currently being developed across 14 economic and development sectors/domains; additional updates (including links) are published by the Commission, when they become available.
Source: https://digital-strategy.ec.europa.eu/en/policies/data-spaces

The AI is becoming a driving force of the EU-wide economies, both in the tech sector and beyond as it provides new solutions across industries. To be able to compete in this new global market, the EU must be able to fuel AI with high-quality data. The Data-Union Strategy addresses this need for high-quality data in Europe, with the aim of exploiting the untapped potential of data and completing the Single Market for data. The Data Union Strategy was adopted in November 2025; it made proposals to further expand data spaces, including with the introduction of a Common European Data Space on defense.
The strategy identified 3 priority areas for action based on:
= scaling up access to data for AI to ensure that businesses have access to high-quality data needed for innovation;
= streamlining data rules to give legal certainty to businesses and reduce compliance costs, and
= safeguarding the EU’s data sovereignty to strengthen European global position on international data flows.
Source and citations from: https://digital-strategy.ec.europa.eu/en/policies/data-union

One year after
After one year of the Data Act’s application, it is vital to visualise how the new rules work in day-to-day practice.
First, it is necessary to look at the non-binding Model Contractual Terms (MCTs) and the Standard Contractual Clauses (SCCs), as well as discuss what they mean for contract drafting, negotiation and remaining party autonomy.
Second, to introduce the latest guidance tools developed by the European Commission, including practical tips on how to use them.
Finally, there is a need to focus on key issues such as reasonable compensation for data access, the protection of trade secrets, compliance with data protection law, as well as looking at the “cloud switching” and the applicability of the Data Act to SaaS.
Thus, the main perspective topics include: – Data Act and Digital Omnibus; – Model Contractual Terms (MCTs) in legal practice; – New guidance tools; – Reasonable compensation for providing data access; – Protecting data and trade secrets in Data Act compliance; and – Cloud switching and SaaS.
General source the EU Regulation “on harmonised rules on fair access to and use of data”, in: https://eur-lex.europa.eu/eli/reg/2023/2854/oj

Law’s key milestones and impacts
= Cloud Provider Switching: Customers now possess expanded rights to switch seamlessly between different data processing and cloud service providers. Vendors are removing technical and contractual barriers to data migration, preparing for complete fee eliminations.
= Connected Device Data: Users (both consumers and businesses) can access raw data generated by Internet of Things (IoT) products, such as smart appliances, cars, and industrial machinery, and share it with third-party service providers.
= Contractual Fairness: Unfair contractual terms regarding data access and use unilaterally imposed on small and medium-sized enterprises (SMEs) are now legally prohibited.
= Upcoming “Data by Design”: While the bulk of data-sharing and switching rules apply, the strict “data by design and default” manufacturing requirements for new connected products will phase in by September 2026.

Data act: key legal focal points
The EU Data Act (Regulation 2023/2854) was published November 22, 2023, entered into force January 11, 2024, and became applicable on September 12, 2025.
Main obligations are now in force with additional requirements phasing in through 2027.
= Some data legislation’s obligations applied from September 12, 2025 (Articles 4-5: data access and third-party sharing);
= Cloud switching provisions applied from September 12, 2025 (customer switching rights);
= September 12, 2026: “Data by design” obligations are applied for connected products placed on market after this date
= September 12, 2026: Enhanced interoperability requirements for cloud services
= January 12, 2027: Complete ban on charges for switching between data processing services
= September 12, 2027: Full implementation of data portability standards and unfair terms rules extend to pre-2025 contracts.
Source and reference from: https://www.fiskil.com/eu-data-act/timeline

For businesses trying to align with the regulation, the European Commission has provided a couple of essential web-guidelines:
= The European Commission Data Act Explained Page outlines the core principles and scope of the legislation.
=Access Official European Commission Data Act FAQs to check detailed guidelines on data access, model contracts, and compliance.

Data Act and Digital Omnibus
The European Commission’s Digital Omnibus is a sweeping reform package that aims to simplify and consolidate the EU’s complex digital rulebook. It overhauls several foundational tech and data regulations to cut compliance costs.
The Digital Omnibus impacts the broader regulatory landscape in a few key ways: = Merging Data Regulations: It streamlines the European non-personal data framework by consolidating three separate instruments—the Data Governance Act, the Open Data Directive, and the Free Flow of Non-Personal Data Regulation—directly into a restructured Data Act. = Revising the GDPR & e-Privacy: The omnibus updates definitions and tracking requirements, aiming to make it easier for European AI developers to train their models on high-quality datasets while drawing criticism from privacy advocates who argue it weakens digital rights. = Cybersecurity Alignment: It introduces a single-entry point for reporting cybersecurity incidents, simplifying a previously fragmented reporting process across multiple laws.
For businesses and public entities trying to navigate compliance, the changes to the Data Act are particularly significant: =Trade Secret Protection: The omnibus introduces new safeguards that allow data holders to refuse data sharing with users if there is a substantial risk of trade secrets being illegally acquired or disclosed to entities in third countries. = Narrowed B2G Data Sharing: Public authorities’ ability to demand private company data has been heavily narrowed. Broad access is replaced with targeted triggers restricted strictly to public emergencies. Additionally, micro and small businesses can now claim compensation when forced to hand over this data. = Removal of Smart Contract Rules: Article 36 of the original Data Act, which mandated specific interoperability and security requirements for smart contracts, is proposed for deletion to prevent unintended regulatory burdens on early-stage innovation. = Cloud Switching Relaxations: The omnibus introduces targeted exemptions regarding the cloud-switching rules for SMEs and specific types of highly customized IT environments to save businesses time and money.
More in: https://ec.europa.eu/commission/presscorner/detail/en/ip_25_2718
Additionally, on Digital Omnibus and AI Regulation, in: https://digital-strategy.ec.europa.eu/en/library/digital-omnibus-ai-regulation-proposal

Cloud switching and SaaS
The EU Data Act introduced mandatory cloud switching rights that limit vendor lock-in for Software as a Service (SaaS) and other cloud services in the EU member states. These regulations grant customers the right to cancel contracts with a maximum two-month notice period, require seamless data portability and phase out switching fees. The EU data legislation reshapes how SaaS providers and customers manage vendor transitions.
The Act’s key features include:
= Shortened Exit Windows: customers can terminate contracts at any time regardless of the initial commitment length, with a maximum notice period capped at two months.
= Data Portability: providers must port all exportable data and digital assets to a new cloud provider or on-premises infrastructure within a strict 30-day transition window.
= Elimination of Switching Charges: all switching, egress, and data-transfer fees are prohibited, ensuring customers face no financial penalties for migrating their digital workloads.
= Mandatory Interoperability: SaaS vendors are obligated to make open, standardized interfaces and formats available so subsequent providers can ingest data smoothly.

The Data Act’s Regulation (2023/2854) introduced a comprehensive framework to enhance data portability and reduce vendor lock-in across the EU digital economy. One impactful component is the cloud switching regime, which establishes broad obligations to facilitate switching between “data processing services.” For providers of cloud-based services, such as Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS)), these rules may present contractual, technical and commercial challenges.
Thus, according to law, “the data” is defined as any digital service provided to customers (not to be confused with data processing) that “enables ubiquitous and on-demand network access to a shared pool of configurable, scalable and elastic computing resources of a centralised, distributed or highly distributed nature that can be rapidly provisioned and released with minimal management effort or service provider interaction.”
This definition is deliberately broad and may raise interpretation questions and legal uncertainties. What is clear, however, is that the cloud switching provisions extend beyond traditional hyperscale cloud providers. The new cloud switching regime explicitly targets “a substantial number of services with a very broad range of different purposes, functionalities and technical set-ups,” including IaaS, PaaS and SaaS offerings – provided they qualify as data processing services under the mentioned definition.
More in: https://www.gtlaw.com/en/insights/2025/9/cloud-switching-under-the-eu-data-act
Additionally, on “mandatory switching rights for fixed-term SaaS models”, in:
https://www.twobirds.com/da/insights/2025/the-data-act-what-mandatory-switching-rights-mean-for-fixed-term-saas-models

 

 

 

 

 

 

Leave a Reply

Your email address will not be published. Required fields are marked *

ten − 4 =